PT-2022-24890 · Gocd · Gocd

Published

2022-10-14

·

Updated

2022-10-21

·

CVE-2022-39309

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions GoCD versions prior to 21.1.0
Description The issue affects GoCD, a continuous delivery server that automates and streamlines the build-test-release cycle for continuous delivery of products. It leaks the symmetric key used to encrypt/decrypt secure variables/secrets in the GoCD configuration to authenticated agents. A malicious or compromised agent may expose this key from memory, potentially allowing an attacker to decrypt secrets intended for other agents or environments if they also obtain access to encrypted configuration values from the GoCD server.
Recommendations For versions prior to 21.1.0, update to GoCD version 21.1.0 to resolve the issue. At the moment, there are no known workarounds for this issue.

Exploit

Fix

Information Disclosure

Exposure of Resource to Wrong Sphere

Weakness Enumeration

Related Identifiers

CVE-2022-39309
GHSA-F9QG-XCXQ-CGV9

Affected Products

Gocd